Mozilla Firefox Multiple Vulnerabilities
Last Update Date:
25 Mar 2015
Release Date:
23 Mar 2015
3697
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Mozilla Firefox, which can be exploited by remote attackers to bypass certain security restrictions and compromise a user's system.
- A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a flaw in processing SVG format content navigation and bypass same-origin policy to execute arbitrary scripts with elevated privileges.
- A remote user can create specially crafted HTML that, when loaded by the target user, will trigger a heap overflow in the JavaScript just-in-time compilation (JIT) engine and execute arbitrary code on the target system.
Impact
- Elevation of Privilege
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Mozilla Firefox version prior to 36.0.3
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 36.0.4, ESR 31.5.3
Vulnerability Identifier
Source
Related Link
Share with